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In this paper we propose a hybrid model of a neural oscillator, obtained by partially discretizing a 
well-known continuous model. Our construction points out that in this case the standard techniques, 
based on replacing sigmoids with step functions, is not satisfactory. Then, we study the hybrid model 
through both symbolic methods and approximation techniques. This last analysis, in particular, al- 
lows us to show the differences between the considered approximation approaches. Finally, we focus 
on approximations via e-semantics, proving how these can be computed in practice. 



Introduction 



Neural oscillations are rhythmic and repetitive electrical stimuli which play an important role in the 
activities of several brain regions. Some examples of brain locations in which it has been demonstrated 
the central role of neural oscillations are the cortex JTTIl . the thalamus lfl8l . and the olfactory information 
processing [8 ]. With the aim of understanding neurophysiological activities, we propose the modeling of 
oscillatory phenomena exploiting hybrid automata. 

A continuous model of a single oscillator based on an ordinary differential system has been proposed 
in |[T9l . Even if this is a simple model, its analysis and the analysis of its composition in multiple copies 
is limited due to the non-linearity of the ordinary differential system involved. For this reason, we are 
interested in the development of a piecewise affine hybrid automaton which correctly approximates the 
continuous model and on which automatic analysis and composition can be made. 

Trying to linearize the non-linear components of the original continuous model, we first replace in 
the standard way the sigmoidal behaviours with sign functions ll9l [T4l . approximating continuos signals 
with discrete off-on signals. Unfortunately, the behaviour of this model differs from the original one. For 
this reason, we propose a more sophisticated approximation of sigmoidals based on a piecewise linear 
function exploited in the development of a hybrid automaton which simulates a single oscillator. 

It is well known that the reachability problem over hybrid automata is source of undecidability. 
Moreover, the exact computation of the reachable sets of hybrid automata, which represents the basis of 
the automatic analysis of the models, does not always reflect the behaviour of the real modeled systems. 
This is due to the fact that real systems are often subject to noise, thus their evolutions do not correspond 
to a single precise formalization. This has been noticed already in |[T9l in the specific case of the continu- 
ous model of the neural oscillator. For these reasons, we study our hybrid automaton exploiting different 
approximation techniques that introduce noise. 

In the literature, several approximation techniques have been proposed (see, e.g., ll7l [T6l[T0l l3l[T5l). 
Franzle in [7 ] presents a model of noise over hybrid automata. The introduction of noise ensures in many 
cases the (semi-)decidability of the reachability problem. Another result of (semi-)decidability always 
based on the concept of perturbation and concerning the safety verification of hybrid systems is given by 
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Ratschan in |fl6l . Furthermore, £-(bi)simulation [10] relations, which are essentially relaxations on the 
infinite precision required by simulation and bisimulation, represent tools able to remove complexity and 
undecidability issues related to the analysis of the investigated model. Moreover, in Q it is presented a 
different approach based on the reinterpretation of the standard semantics of the formulas which compose 
hybrid automata. Exploiting this new class of semantics, called £-semantics, the authors provide a result 
of decidability of the reachability problem over hybrid automata with bounded invariants. 

In this paper, we focus precisely on the approximation approach based on the £-semantics. In par- 
ticular, we propose a translation that allows us to reduce the £-semantics evaluation to the standard 
semantics evaluation, computable by exploiting tools for cylindrical algebraic decomposition. Then, we 
present some properties which have been automatically tested on the neural oscillator by applying such 
translation. Hence, in this work, we prove both that £-semantics better represents the real behaviour of 
the neural oscillator, than the standard one, and that the approach is effective. 

The paper is organized as follows: Section [T] gives some basic definitions concerning logics and hy- 
brid automata; Section [2] is dedicated to the mathematical modeling of the neural oscillator; in Section [3] 
we present different approximation techniques based on noise, perturbation, approximate (bi)simulations, 
and £-semantics. Section [4] exposes some considerations regarding the application of the previously pre- 
sented approximation approaches to the investigated model. Finally, in Section [5j we first define a 
translation which make effectively computable the £-semantics, then we experimentally exploit it in the 
analysis of the hybrid automaton which models the neural oscillator. All the proofs can be found at 
http : //www. dimi .uniud. it /piazza/hsb20 12_extended.pdf. 

1 Hybrid Automata 
1.1 Preliminaries 

We formally define hybrid automata by using first-order languages and, because of that, we first need to 
introduce some basic notions and our notation. 

We use X, X, Y, Fj, W, and Wj to denote real variables and X, Xj, Y, Yi, W, and Wi to denote tuple 
of real variables. We always assume that all the variables that occur bound in a formula do not occur free 
and vice versa. This enables us to label variables, rather than occurrences, as free or bound. We write 
(p[X\,. . . ,X m ] to stress the fact that X\, X m are free in (p. By extension, <p[Xi, . . . ,X n ] indicates that 
the components of vectors Xi, . . ., X„ are free in (p. 

The formula obtained from <p[Xi , . . . ,X m ] by replacing Xj by so, where sq is either a constant or a vari- 
able, is denoted by <p[X,-/jo]- By extension, <ppQ . . .Xi +n /so ...s n J indicates the formula obtained from 
(p[X\ , . . . ,X m ] by simultaneously replacing all the variables X . . .X, +; , by sq . ■ . s n . If X = (Xi, . . . ,X + „), 
so = (so,...,s n ), s\ = (s n +i,...,S2*n+i)> an d — . is a relational symbol (e.g., = or >), then we may 
write (ppL/soj in place of (plX . . .X i+n /s Q . . .s„j and s '=. s\ in place of Aye[o,«] (sj'=.Sj+k* n ) (e.g., 
(7,X) = (2,3) means 7 = 2 AX = 3). Finally, if <p[Xi, . . . ,Xj, . . . ,X„] then we may denote the formula 
<p[Xi/Sl by writing <p[Xi, . ,X„]. 

The semantics of a formula is defined in the standard way (see. e.g., 10). Given a set T of sentences 
and a sentence <p, we say that (p is a logical consequence of Y (denoted, Y \= (p) if <p is valid in any 
model ^# in which each formula of Y is valid too \= Y). A theory SF is a set of sentences such that 
if \= <p, then <p 6 2? . A theory 2? admits the so-called elimination of quantifiers, if, for any formula 
(p, there exists in 2? a quantifier free formula p such that cp is equivalent to p with respect to 3*. If there 
exists an algorithm for deciding whether a sentence (p belongs to 3T or not, we say that 3* is decidable. 
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Example 1. Consider the formula (p = 3X (a * X 2 + b * X + c = 0). It is well known that cp is in the 
theory of reals with +, *, and > if and only if the unquantified formula b 2 —4ac > holds. 

1.2 Syntax, Semantics, and Reachability 

A hybrid automaton is an infinite state automaton that consists in a set of continuos variables and a finite 
directed graph. Each node of a graph is labelled by both an invariant condition and a dynamic law, while 
all the edges are tagged with an activation region and a reset map. The continuous variables evolve 
according to the dynamic law of the current node of the graph and the node's invariant condition must be 
satisfied along all the evolution. An edge is crossable if and only if the variable values are included the 
activation region and, when a hybrid automata jumps over it, the associated reset map is applied. 
Definition 1 (Hybrid Automata - Syntax). A hybrid automaton H of dimension d(H) G N is a tuple (X, 
X', V, £, Inv, f, Act, Res) where: 

• X = {X\, . . ., X n ) and X' = (X[, . . ., X„) are two vectors of variables ranging over the reals M; 

• (V, £) is a directed finite graph, i.e., £ C V x V. Each element ofV will be dubbed location; 

• Each location v £V is labelled by both a formula Inv(y)\X], called invariant, and a continuous 
function f, : W — > (M>o — > W), called dynamics or flow function. The dynamics may be 
specified either by differential equations, i.e., f, is the solution of a given Cauchy problem, or by 
a logic formula. We use the formula Dyn(v)[X,X' ,T], where T is a temporal variable ranging in 
M>0, to denote the dynamics on v, i.e., Dyn(v)[X.,X.' ,T] = X' = f v (X) (T); 

• Each e G £ is labelled by the formula; Act (e) [X] and Res (e) [X, X'] which are called activation and 
reset, respectively. 

If all the formulae that define a hybrid automaton H belong to the same logical theory 3*, then we 
say that H is definable in 3? or that H is a 3* hybrid automaton. 

The semantics of any hybrid automaton can be specified as a transition system that is composed by 
two different relations miming the double nature of the hybrid automaton itself: the continuous reacha- 
bility transition relation and the discrete reachability transition relation. 

Definition 2 (Hybrid Automaton - Semantics). A state a ofH is a pair (v,r), where v <EV is a location 
and r G W 1 ^ is an assignment of values for the variables o/X. A state (v,r) is said to be admissible if 
/nv(v)|r] holds. 

The continuous transition relation Ac between admissible states, where t > denotes the transition 
elapsed time, is defined as follows: 
(v,r) A c (v,s) <==>- r = / v (r)(0), s = f,(r)(t), andlnv{v)\f v (r)(t')\ hold for each t' G [0,t]. 
The discrete transition relation A# among admissible states is: 

(v,r) Ao (v,s) <^=^> e = (v,v'} and both Act {e)\r\ and Res(e)\r,s\ hold. 

We write a — >c a' and a ->o to mean that there exists a t G M>o such that a Ac a' and that there 
exists an e G £ such that a — >d a', respectively. 

Definition 3 (Reachability). Let J* be either N or an initial finite interval o/N. A trace ofH is a sequence 
of admissible states ao,ai,..., a with j G J? , such that — > a, holds for all i G [1,«] and either 
- >C fl'i-i —>D Qi, CLi-2 —>D <*i-l du or fl r ! _2 — >d <*i-\ ciifor each i G /\ {0j[j] 
The automaton H reaches a state a n from a state ao if there exists a trace ao, . . . ,a n . In such a case, 
we also say that a n is reachable from ao in H. 

'This last condition supports not transitive dynamics. See |4| for a complete discussion. 
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The problem of deciding whether a hybrid automaton H reaches a set of states S from a set of states 
R is known as the reachability problem of S from R over H. A trace produced by an infinite sequence 
of discrete transitions during a bounded amount of time is called Zeno trace and every hybrid automaton 
allowing such kind of trace is said to have a Zeno behaviour. 

Example 2. Let us consider a hybrid automaton Hjj modeling a bouncing ball whose collisions are 
inelastic. The automaton is equipped with two continuous variables X\ and X2 that represent ball's 




Figure 1 : Bouncing ball hybrid automaton. 



elevation and velocity, respectively. The dynamics, resets, and discrete structure of Hi, are presented in 
Fig. [7] The two coefficients g and 7 are the standard gravity and the coefficient of restitution, respectively. 
The activation formula of the automaton edge is "X\ = 0". 

Imposing as starting height ho = 10m and as coefficient of restitution 7 = 0.86, the bounce peaks 
decrease at each iteration and the automaton Hb has a Zeno behaviour. 

As the halting problem for the two counter machine can be reduced to the reachability problem of 
a particular class of hybrid automata, the reachability problem for hybrid automata itself is not always 
decidable [1]. However, if H is a ^-hybrid automaton and 2? is a first-order decidable theory, then 
the reachability through a bounded number of discrete transitions can be characterized with a first-order 
decidable formula (see e.g., [4]). In particular, in the case of automata defined through polynomials over 
the reals, we can use cylindrical algebraic decomposition tools to decide bounded reachability. 



2 Neural Oscillator: Continuous and Hybrid Models 

Oscillatory electrical stimuli have been considered central for the activities of several brain regions since 
the begin of the '80s. It was shown that they play an important role in the olfactory information pro- 
cessing [8] and they were observed in the thalamus ifTSl . and in the cortex ifTTIl . Many studies suggested 
that, in the mammalian visual system, neurons signals may be group together through in-phase oscilla- 
tions [11]. Because of this, the development and analysis of models representing oscillatory phenomena 
assume a great importance in understanding the neurophysiological activities. 

A simple continuous model of a single oscillator has been proposed in |[T9ll . The model describes 
the evolutions of one excitatory neuron (N e ) and one inhibitory neuron (Ni) by mean of the ordinary 
differential system. 

f(r r\ S £ = -^+tanh(A*X e )-tanh(A*X / ) 

J[T ' A) ■ \ X i = -f + tanh(A*X e ) + tanh(A*X ; -) ' W 

where X e and X, are the output of N e and A^, respectively, X is a characteristic time constant, and A > 
is the amplification gain. Hopf bifurcation characterizes a qualitative change in the evolution of /(t, A): 
if T* A < 1, then the point (0,0) is the unique global attractor of the system, if, otherwise, T * A > 1, 
the origin is an unstable equilibrium and all the evolutions converge to a limit cycle attractor 13. A 



simulation of /(3, 1) is represented in Fig. 4(a) 
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(a) The automaton has 4 locations. The dashed lines 
denote both the boundaries of the invariants and the 
activation regions. The resets are identify functions. 



(b) Direction field and evolution of the automaton from the two 
points { — j, — j) and ( — 1,6) when T = 3. The automaton has 
four attractors, is not periodic, and its principal axes are stable. 



Figure 2: The piecewise hybrid automaton associated to the function /(t). 



Even if f[x,X) is rather simple, the ability of analyzing a complex system obtained by composing 
multiple copies of this model is limited due to the non-linearity of f{%, A) itself. For this reason, we are 
interested in the development of a piecewise affine hybrid model whose behaviour fairly approximates 
System ([T]) and that can be automatically analyzed and composed. 

Since the non- linear components in System ([I]) have the form tanh (A *X), we try to linearize such 
function. In the case of genetic networks it is quite standard to approximate sigmoidal behaviours (e.g., 
tanh) through the sign function sgn (9JO. Such approximation replaces a continuous signal with a 
discrete off-on one. In our case, by replacing tanh (A *X) with sgn(X) in System ([!]), we obtain the 
following differential system: 



/(*): 



X, 



-f + sgn(X, 

X] 



(2) 



-sgn(X,-) 
Xt = -% + sgn(X e )+sgn(X ! ) ' 

which corresponds to the piecewise hybrid model depicted in Fig. |2(a) Unfortunately, the behaviour 
of t his m odel is quite d iffere nt from that of System ([T}, as we can see comparing the simulation in 
Fig. 2(b) with that of Fig. 4(a) In particular, the model based on f(x) has four attractors with coordinates 
(—2 * T,0), (0, — 2 * t), (2 * T,0), and (0,2 * z), it is not periodic, and its principal axes are stable. 
A more sophisticated approximation of tanh (A *X) is the piecewise linear function: 



*z 



if z < 
if 



ifz>f 



a 
A 



(3) 



where a is the approximation coefficient which determines the slope of the central segment. The substi- 
tution of tanh (A *X) with h Xa (z) in System (|TJ) leads to the system: 

A', 



X e 

X, 



Xi 



+ h^ a (X e )-h k>a (Xi) 
+ h x JX e )+h l JX i ) 



(4) 
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whose corresponding hybrid automaton is depicted in Fig. [3] A different approximation could be ob- 
tained by using the technique proposed in lfl2l . 
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Figure 3: A graphical representation of the hybrid automaton Hj associated to the function f a (z,X). 

In the rest of the paper we present some general techniques for studying hybrid automata and then 
we apply them to to formally prove its properties. 

3 Approximation Techniques 
3.1 Noise and Disturbed Automata 

The density of continuous variables provide an unbounded quantity of memory within a bounded region. 
As a matter of fact, the undecidability results proved in [ 13 ] are based on the possibility of embedding N 
in (0, 1]C1 through the function f(n) = 2~ n . 

However, Franzle in [7 ] observed that noise disturbes the trajectiories of real hybrid systems, aug- 
menting the set of reachable points. Hence, in [7 ] a model of noise has been presented over hybrid 
automata. Remarkably, the introduction of noise ensures in many cases the (semi-)decidability of the 
reachability problem. 

Our definitions of hybrid automata slightly differ from the ones in [7]- In particular, as far as the 
syntax is concerned, the formulas Acf(e)[X] and Res(e)[X,X'} are glued together in a formula called 
trans e [X,X']. Moreover, our formulae Znv(v)[X] and Dyn(v)[X,X' ,T] are replaced by a single formula 
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(a) An evolution of /( 3, 1). (b) An evolution of /2(3, 1). 

Figure 4: Direction field and evolution of the models discussed in Section [2] 

act v [X,X'] whose meaning in our framework is: 

3t(t > o ax' = / v (x)(r) Avr'(o <r <t^ /w(v)/ v (x)(r'))), 

i.e., the formula act v \X,X'] syntactically ensures the existence of a continuous transition. Exploiting 
these relationships between our hybrid automata and the hybrid automata defined through the formula? 
act v [X,X'] and trans e [X,X'], we can reformulate the results presented in Q in our framework. 

Definition 4. Given a hybrid automaton H = (X, X', V, £, Inv, /., Act, Res) we say that the hybrid 
automaton H = (X, X', V, £, Inv, /., Act, Res) is a disturbed variant ofH if for each pair of states a, a' if 
a — >c a' in H, then a — >c a' in H. 

Moreover, let 8 be a distance over M. d ^ and e G M>n- H is a disturbance of noise level e or more if 
for each s, s' such that 8 (s, s') < £ it holds that if (v, r) — >c (v, s) in H, then (v, r) — >c (v, s') in H. 

Intuitively, when there are no bifurcation behaviours, a small e ensures that the dynamics of H are 
close to those of H. 

In it has been proved that in the case of bounded invariants there exists a finite computable index 
i G N such that the reachability over H can be over-approximated with reachability within i discrete 
jumps over a disturbance of noise level e or more of H. 

Theorem 1. [7] Let 2f be a decidable first-order theory. Let H,H be ST hybrid automata, with H 
disturbance of noise level £ or more of H for some £ G M>o- There exists i such that for all pairs of 
states a, a! if a reaches a! in H, then a reaches a' in H within i discrete transitions. Moreover, i can be 
effectively computed. 

Unfortunately, there are cases in which the over-approximation is always strict, no matter how small 
£ is. Such automata are called fragile, in contrast with robust automata, where if a does not reach a' 
in H, there exist £ G M>o and H disturbance of noise level £ such that a does not reach a' in H. As a 
consequence, reachability is decidable over robust automata, while it is only semi-decidable over fragile 
automata. It is not possible to decide whether a hybrid automaton is robust or fragile. Intuitively, since 
real world systems are always subject to noise, a hybrid automaton is a reliable model of the real system 
only if it is robust. So, it is fundamental to develop and exploit design techniques which ensure robustness 
of the resulting hybrid automata. 
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3.2 Approximate Bisimulations and Simulations 

Since the 90's, simulation and bisimulation have been successfully used to investigate hybrid automata. 
However, due to the infinite precision required to relate different evolutions, these tools are able to remove 
neither the complexity nor the undecidability issues that may affect the analysis of the investigated model. 
The £-(bi)simulation relations ifTOl relaxes these infinite precision requirements by relating system evo- 
lutions whose maximal distance is less than a given a. This enables us to simplify both the dynamics 
and the resets of the investigated automaton. Moreover, provided an observation map {{■)) : R rf ^' — > M d 
that associates the internal status of an automaton H to the values measurable by an external observer, 
£-(bi)simulations allow to relate the "visible" behaviours of H to the behaviours of an automaton whose 
dimension is smaller than d(H). 

Any pair of hybrid automata Hi to H 2 related by an e-simulation must have the same discrete structure 
and share the same locations V and edges £ by definition. 

Definition 5. Let Hi = (Xi, X/, V, £, Invi, f.j, Acti, Res^ be a hybrid automaton for each i G {1,2}. 
Moreover, let e be in R>o. A relation y £ C (V x R d ( ff ')) x (V x R 1 ^ 2 )) is an approximate simulation 
relation of Hi by H2 of precision e if, for all ((vi,n) , (v2,r2)) £ «^e- 
1. v\ = vj = v; 

2- \\((n))i-((r 2 )) 2 \\<e; 

3. if (v,r\) —^c ( v > r 'i) in Hi, there exists r* 2 s.t. (v,r 2 ) Ac {v,r 2 } in H 2 and ((v,r'j) , (v,r^)) G «5*g; 

4. if (v,r\) A/) (v',/j) in Hi, there exists r' 2 s.t. (v,r 2 ) A^ (v',r^) in H 2 and {{y' ,r' x ) , (v 1 ,r' 2 )) G 
The automaton H 2 approximately simulates Hi with precision e if there exists an approximate sim- 
ulation relation of Hi by H 2 of precision e. An approximate simulation relation y e of H\ by H 2 of 
precision e is an approximate bisimulation relation between Hi and H 2 of precision s if the relation 
^jT 1 = {(a 2 ,ai) I {a\,a 2 ) G o5^ e } is an approximate simulation relation of H 2 by Hi of precision e. 

Many methods have been developed to automatically compute approximate simulation relations be- 
tween systems such as constrained linear systems, autonomous nonlinear systems, and hybrid systems. 

3.3 e-Semantics 

The undecidability of the reachability problem over hybrid automata having bounded invariants is a 
direct consequence of the ability of characterizing dense regions of arbitrarily small size. As noticed 
in 0, especially in the study of biological systems, such ability may result misleading. As a matter 
of the fact, the continuous quantities used in hybrid automata are very often abstractions of large, but 
discrete, quantities. In such cases, the ability of handling values with infinite precision is a model artifact 
rather than a real property of the original system. 

In order to discretize the continuous space, we introduce the concept of e-sphere. Given a set S C 
R", the e-sphere B(S,e) is the subset of R" of points at distance less than e from S, i.e., fi(S,e) = 
{q G R" I 3p G S(8(p,q) < e)}, where 8 is a distance function over R" (e.g., the standard euclidean 
distance). Moreover, given a hybrid automaton H and an initial set of points I C M. d ( H \ the set of points 
reachable from the set I by H, denoted by RSetnil), is characterized by RSet H (T) = U;eM^ ef //(^) = 
]imi^ +0 oRSet' H (T) where RSet' H (T) is the set of points reachable from I in at most i discrete transitions. 
Theorem 2 (0). Let 3? be a decidable first-order theory over reals and H be a 8? hybrid automaton 
with bounded invariants. If there exists £ G R>o such that, for each I C and for each i G N, either 

RSet'fl l (I) = RSet' H (T) or there exists an a, G R rf(//) such that «({«;},£) C RSetfi l (I) \RSef H (l), then 
there exists j G N such that RSet' H (I) = RSet J H (I) and the reachability problem over H is decidable. 
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This result finds applications when it makes no sense to distinguish measurements smaller than e. 
Hence, since hybrid automata characterization is based on first-order fromulae, it seems reasonable to 
reinterpret the semantics of semi-algebraic automata by giving to each formula a semantics of "dimension 
of at least e". In [3] the authors introduce a new class of semantics, called e-semantics, which guarantee 
the decidability of reachability in the case of hybrid automata with bounded invariants. 

Definition 6. Let 3? be a first-order theory and let e £ M>o- For each formula \j/ on 2f let \ y\ e Q 

where d is the number of free variables of y, be such that: 

(e) either {] \j/^ e = or there exists p £ W l such that B ({p}, e) C -fl \j/§ e ; 

(H) U/\q>h^Uhn{q>h: (V; pX ¥ [X,X]b e = $/\ reR¥ lr,Xn e ; 

(u) Mv<Ph = MhuM e ; a) ^x ¥ [x,x]b e = qy reR nr,nh; 

Any semantics satisfying the above conditions is said to be an £-semantics for 3F. 

Let us notice that no £-semantics can over-approximate the standard semantics. Infact, for any theory 
2T , if {|0|} C {|0|}e, where {]•[} is the semantics associated to 3T, then {|-i0|} D H^^Hg due to the (-i)-rule. 

Example 3 (The sphere semantics). Let 2? be a first-order theory over the reals and let e > 0. The 
sphere semantics ofy, d^D e , is defined by structural induction on \f/ as follows: 

. {/! o t 2 \, £ o t 2 1 e), for o €{=,<}; . ([VX^|[X,X]D e = dAr€M ^,X]D e ; 

. ^iAvA2^ = U B (M !e )c (v/I ) E n(^ e B (M» e ).- • $3xyr[x,nk-Wr&iV[r>W e ; 

• lYlVV2h-Me U Me>' * hYh-DB({p},e)nM e =(!> B ({p}^)- 

£-semantics are exploited in the reachability algorithm defined in [3]. Intuitively, the algorithm 
computes reachability incrementing the number of allowed discrete transitions at each iteration. New 
reachable sets of points are computed until they became too small to be captured by the £-semantics. In 
the case of hybrid automata with bounded invariants, it always terminates. Finally, notice that replac- 
ing the £-semantics with the standard one, the above algorithm could not terminate even with bounded 
invariants, due to Zeno behaviours. 

To conclude, let us notice that, by Taylor's approximation, for any £ and any differentiable function 
/(f), if we fix a time horizon?/,, we can approximate /(f) by a polynomial p(t) such that p(t)\\ < £ 

for all t G [0, ?/,] . Hence, there are £-semantics that are not able to distinguish p(t) and f(t) and, according 
to such £-semantics, we can use p(t) in place of f(t) for all t £ [0,7/,]. It follows that, adopting an 
opportune £-semantics, the Tarski's theory (i.e., the first order theory of the inequalities over the reals) is 
enough to represent any differentiable function f(t). 



4 Approximated Analysis over Neural Oscillator 

In this section we try to understand what happens when we apply the approximation techniques described 
in Section|3]to our neural oscillator hybrid model Hj presented in Section|2j 

4.1 £ -disturbance 

The automaton Hf presents two main behaviours: (0,0) is an unstable equilibrium; each starting point 
different from (0,0) reaches the limit cycle. For this reason we can prove that H? is fragile. As a matter 
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of fact, if Hj is a disturbance of noise level £ of Hj, then (0,0) in Hj> reaches points different from 
(0,0), while in Hj it does not. In other words, if we consider backward reachability, (0,0) is backward 

reachable in Hj from a region R ^ {(0,0)}, while in Hj it is backward reachable from {(0,0)}. This is 
not due to the fact that (0,0) is unstable, but to the presence of two limit behaviours over a connected 
region. We recall that in a piecewise hybrid automaton the invariants are connected disjoint regions 
whose union is connected and the resets are identities, i.e., the trajectories are continuos. We use the 
term limit behaviour of a hybrid automaton to denote both equilibria and limit cycles. 

Theorem 3. Let H be a piecewise hybrid automaton presenting at least two different limit behaviours. 
If from each point there is a unique possible evolution, then H is fragile. 

The above result points out that there are systems for which it is not possible to define robust models. 
In |[T6l a model is said to be safe only if it remains safe under small disturbances. In this terms our 
result shows that there are systems which do not admit a safe model. This does not means that they 
are not interesting or that we need to remove some of their behaviours. This simply means that such 
systems have to be studied applying some form of disturbance or approximation. As the matter of facts, 
if we study them by applying standard semantics, we define a precise border between the points reaching 
different behaviours. Such precise border is not realistic. 

4.2 e-(bi)simulations 

The automaton Hj has both an unstable equilibrium in (0,0) and a single limit cycle encompassing the 
origin of the axes. Because of that we are guaranteed that, during its evolutions, Hj decreases the distance 
of its state from the limit cycle regardless of the starting state s ^ (vq, (0,0)). Since all the differential 
equations defining the dynamics of Hj are continuous, we can define an £-simulation between states 
whose distance from the limit cycle is smaller than e. This enables us to both approximate the non-linear 
differential System ([T]) with a linear differential system and reduce the complexity of the analysis. 

However, if d is the maximum Euclidean distance between (0,0) and the cycle limit, no £-(bi)si- 
mulation, with e < d, can relate (vo, (0,0)) with any other state of Hj. As a matter of fact, the points 
belonging to any neighborhood of (0,0) eventually converge to the limit cycle. It follows that (vo, (0,0)) 
is a singularity of the model and, despite the original system always reaches a periodic evolution, any 
approximation of the proposed model by mean of £-(bi)simulation does not manifest this property. 

4.3 e -semantics 

In order to exploit £-semantics for the study of Hj the first step we have to perform is that of approximat- 
ing through polynomials the solutions of the differential equations defining the semantics. This can be 
done, for instance, by using Taylor polynomials or more sophisticated numerical integration techniques. 
We do this in the next section, where we also apply cylindrical algebraic decomposition tools to auto- 
matically prove properties of our model. Here instead we try to infer some general results about the use 
of £-semantics on Hj. 

Hj has an unstable equilibrium in (0,0). This means that (0,0) reaches {(0,0)}. However, when we 
compute the set of points reachable from (0,0) through an £-semantics we get either the empty set or 
a set having diameter at least £. In particular, if our £-semantics under-approximates the standard one 
(i.e., if {0} D {|0} £ » where {•} is the semantics associated to chosen theory, for each formula 0), then 
we get the empty set. Otherwise, both cases are possible, depending on the £-semantics. For instance, 
in the case of sphere semantics, no matter how we approximate the dynamics, we get that (0,0) reaches 
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a set having diameter at least e. Similarly, unless we use an under-approximation £-semantics or some 
unusual metrics, the limit cycle is transformed into a limit flow tube. This means that, if we consider a 
point on the limit cycle and we compute the set of points reachable from such point, then we do not only 
obtain the limit cycle, but at least a flow tube which includes the limit cycle. We will see some more 
details on this in the case of sphere semantics in Section [5] All the other points, again, will reach either 
the empty set or a set having diameter at least e. The result we would expect in this second case is that 
each point in the space reaches the flow tube including the limit cycle. We will see that this is true in the 
case of sphere semantics, even when we use the simplest Taylor polynomials of degree one. 

These considerations already allow us to point out that sphere semantics better reflects the real system 
behaviour than the standard one. 



5 Computing Sphere Semantics 

In this section we show how sphere semantics can be computed exploiting tools for cylindrical algebraic 
decomposition. In particular, we introduce a translation from sphere semantics to standard semantics. 
Then, we apply the translation to study the "sphere" behaviour of our neural oscillator example. 

5.1 A translation into standard semantics 

If 3? is a first-order theory and 8 is a distance definable in 2F, then the sphere semantics of any formula 
in S? is ^-definable in the standard semantics, i.e., for any formula <p[X] G 3? we can compute a formula 

(f) E [X] G ST such that (|<p[X]} e = { 5) e [X] } for all e G M> - 

In order to achieve this goal, we need to distinguish two kind of variables: the variables of the original 
formula (named W, Wj, W and Wj), whose evaluations follow the rules of the sphere semantics, and the 
auxiliary variables (named Y , F,-, Y and Yi) that will be introduced to encode the sphere semantics into 
the standard one. From the point of view of the sphere semantics the later can seen as symbolic constants, 
even if they will be quantified in the formula (<p) e . In particular, we will use them to characterize sets of 
the form dAreR^lfa^lDe anc ^ dV,-eR < P[I r iW]][) e in the standard semantics. 

Definition 7 (Translation). Let 3? be a first-order theory over the reals, <p[Y .W] be any first-order 
formula 3? -definable, and £ € M>o- We define (<p) e [Y,W] by structural induction on <p[Y.W] itself. 

1. ((/! o^)[Y,W]) e *3W ((fi of 2 )[Y,W ] A5(W ,W) < e), for o g {=,<}; 

2. (^^'(avft; 

3. (0[Y,W]A?[Y,W]) e = / 3Wo(VW 1 (5(W ,W 1 ) < e ((f) e A (v) e )[Y,Wi]) A5(W , W) < e); 

4. (Vwf\Y(w,W]) £ = 3W (VWi(5(W ,Wi) < e -> VF(0[YXWi]) e ) A 5(W , W) < e); 

5. (3W<MY>,W]) E = / 3y(^[Y^VW 1 ]) e ; 

6. (^]Y>]) e ^3Wo(VWi(5(W ,Wi) < £ -> -(^[Y?Wi]) e ) A5(W ,W) < e). 

Theorem 4 (Semantics Equivalence). Let 3? be any first-order theory and 8 be a 37 -definable distance. 
The sphere semantics \ of 3? is 3? -definable in the standard semantics and, in particular, \ (p [X] [) e = 

| (<p) £ [X] | for any formula <p[X] G 3? and all s G M>o- 
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Since (<p) £ [Y W] is definable in Tarski theory, and this theory is decidable, the satiability of <p in (J [) e is 
decidable. 

Let us notice that the application of the translation in Definition [7] to a formula, increases the eval- 
uation complexity of such formula with respect to its untranslated version. This is mainly due to the 
possible introduction of quantifier operator alternations. 

5.2 Experimental Results on the Neural Oscillator 

Let us consider the hybrid automaton Hj described in Section |2] for modeling a neural oscillator. We 
intend to study its behaviour through sphere semantics, exploiting cylindrical algebraic decomposition 
tools to automatically compute it. 

As we noticed in Section [3] any differentiable dynamics can be exactly represented, in terms of an 
opportune £-semantics, by a semi-algebraic function. In particular, we can replace the dynamics of Hj 
by the corresponding Taylor polynomials up to a certain degree which depends on e. In this paper, we 
decided to model the automaton dynamics by using their first-degree Taylor polynomials and we obtained 
the automaton H'~ depicted in Figure |5j In order to keep the presentation simple, in this section we fix 
the parameters as follows z = 3, X = 1, 05 = 2. Hence, the activations correspond to the axis X; = ±2 
and X e = ±2. 
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Figure 5: The piecewise hybrid automaton H~ associated to the function /2(3, 1). 

A simulation of Hj is presented in Figure |4| a limit cycle is still present, but it has a diamond- 
like shape. We are interested in studying this limit cycle. In particular, we are interested in proving, 



70 



Hybrid Automata and e-Analysis on a Neural Oscillator 



exploiting tools for symbolic computation, that if we apply sphere semantics, each point in the space 
reaches a bounded region which includes the limit cycle. In this example our automata have unbounded 
invariants, hence the termination of sphere semantics reachability algorithm is not guaranteed. 

We start computing the intersections of the limit cycle with the activation regions. Consider for 
instance the intersection Qo = (xq , 2) of the limit cycle with X = 2 and X e > 0. We have that xq is 
the unique solution of the equation which describes the intersection of the diamond-like limit cycle with 
Xj = 2. Similarly, consider point Q\ = (2,yQ 1 ) that in turn corresponds to the intersection of the limit 
cycle with X e = 2 and X > 0. We effectively calculated all these intersections by using the computer 
algebra system Maxima. So, for instance, we getjcg = 3 ^^+j^ 8 and yg, = ™ • ^ ne P°i nts 
Qo and <2i satisfy the activation formulae wich regulate the discrete transitions between locations v§ and 
V5, and locations V6 and w, respectively. Let us now consider a point Po located on X,- = 2, but which is 
such that its distance do from Qo is at least 2s, i.e., Po = (xp ,2) and 8(Qo,Po) = do > 2s. Consider now 
any point Pi on X e = 2 resulting from the sphere semantics evaluation of the continuous evolution which 
starts in Po inside location V(,. Thus, let denote with d\ the distance between such Pi and Q\. 

If we could prove that d\ is always smaller than do, then we would be able to conclude that all the 
points which start from a distance of at least 2s from the limit cycle converge to a flow tube having 
diameter 2s that includes the limit cycle. Of course, to obtain such conclusion, we need to prove this 
property on all locations. 

We can formalize this concept through a first-order formula. We denote with r and s the straight lines 
X = 2 and X e = 2, respectively, and with the notation Qo 6 rC\CnX e > the membership of Qo to the 
intersection of straight line r with limit cycle C and positive X e semi-plane. Moreover, with the notation 
dP) — >c Pi D e we denote the continuous transition from point Po to point Pi performed exploiting sphere 
semantics. Thus, our desired property can be expressed as: 

V£o2iVP Pi((Go e mcnx e >0A2i e sncnXi >oap g mx e >oa 

p esnx e >OA5(2o,Po) >2£A^P ^ c Pi^)^5(ei,Pi) <5(2o,Po)) (5) 
stating the convergence to the limit flow tube in location v^. Such property can be easily rewritten for 
each location of the hybrid automaton, changing the roles of activation border lines r and s. 




Figure 6: Two evolutions of the first degree approximation of the model proposed in Section [2j 

We automatically expanded such formula by using a Perl script that implements the Definition [7] to 
translate sphere semantics into the standard one. In particular, (|Po — >c AD e > in the case of location V6 
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becomes 

V[X] = 3r(3X (VX 1 (5(X ,X 1 ) < a -* (T>OA0[X 1) 7l)))A«(Xo,X) < e), (6) 

where 

0[X,T] = 3X (VX 1 (5(X ,X 1 ) < s -> (3X 2 (IIi[X 2 ,7l AS(X 2 ,Xi) < e)A 

3x 2 (n 2 [x 2 ,r] a5(x 2 ,X!) <£))) a5(x ,x) < e), 

Ili [X ,F ,Xi , Fi , 7] = 6 *Xi = 6 *X + (*o - 3 * Y ) * T, and U 2 [X Q ,Y Q ,X Y ,Yi,T\ =6*Y\ = 6* Y + (F + 
3 *Xo) * T. However, we notice that, since II i and n 2 are closed and convex, <p can be simplified as: 

0[X,7] = 3X o (n 1 [Xo,7lAn 2 [Xo,7lA5(X o ,X)<e). (8) 

Similarly, y becomes: 

v/[x] = 3r( r > o a 3x (n j [x , 7| a n 2 [x , r] a 5 (x , x) < £ ) ) . (9) 

So we plugged this last formula in Formula[5]and used REDLOG [5] to test it. The formula turns out to be 
true (the result is computed within few seconds), proving our conjectures. 

Notice that we used Maxima to compute the exact coordinates of the points on the limit cycles since 
that computation does not require quantifier elimination. However, we could have used REDLOG. 

As far as (0,0) is concerned it is immediate to prove through a first-order formula that it reaches 
points different from itself and, hence, it reaches the limit flow tube. 

Other interesting properties that automatically verified express, for instance, the fact that applying 
the sphere semantics there are points that cross the limit cycle (in both directions). This is quite natural 
since points closer than s to the limit cycle get expanded and cross it. 



6 Conclusions 

In this paper we have modeled a neural oscillator constructing a hybrid automaton whose components 
derive from the approximation of the continuous model presented in ||T9l . We have analyzed its be- 
haviours considering the application of some approximation techniques for the introduction of noise, as 
already advocated in |fl9l . In particular, we focused on the approach based on the £-semantics. 

The simulation based on the application of the £-semantics has revealed the any point which begins 
its evolution from a distance of at least 2s from the limit cycle, converges to a flow tube which possesses 
a diameter equal to 2s and that includes the limit cycle. Due to size of the formula; which compose 
the hybrid automaton and the growth of such formalae introduced by the translation of the £-semantics 
evaluations, a direct computation of the reachable set would have high complexity and eventually returns 
results of difficult interpretation. For this reason, we have reformulated the problem in form of a closed 
property which guarantees the convergence of any point towards the limit cycle of the modeled system. 

During the construction of the formula that describes the convergence to the limit cycle, some steps 
of simplification of the formulae have been applied. In particular, we have reduced the complexities of 
translated formulae, relying on the convexity of the sets characterized by some of their subformulae. An 
interesting aspect to investigate is whether these simplification steps can be automatically performed. 

As future work, in order to analyze the behaviour of a group of neural oscillators, we plan to combine 
several hybrid automata and to study their evolutions always adopting £-semantics. 
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